Friday, January 15, 2010

Disable or Remove virus which acts as debugger of explorer.exe

This virus tricked with a small change as other viruses. Other viruses places itself on windows startup which loads them but this virus simply makes a debugger of explorer.exe which is the main execution file of windows. Thus resulting in loading itself everytime windows runs.

Its state as a debugger to explorer.exe is defined by registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe

To unset that either remove that key or rename the explorer.exe file and set the renamed file as the shell name in :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell->renamed filename

No comments:

Post a Comment